Описание
Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additional parameters to read from or inject content into the retrieval-augmented generation (RAG) corpus. On 2026-03-25, AI Assist for Customer restricted network access and enforced authentication for the previously exposed endpoints.
Ссылки
- Technical Description
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2026-03-25 (исключая)
cpe:2.3:a:deloitte:ai_assist_for_customer:*:*:*:*:*:*:*:*
EPSS
Процентиль: 36%
0.00436
Низкий
4.8 Medium
CVSS3
Дефекты
CWE-306
Связанные уязвимости
CVSS3: 4.8
github
около 2 месяцев назад
Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additional parameters to read from or inject content into the retrieval-augmented generation (RAG) corpus. On 2026-03-25, AI Assist for Customer restricted network access and enforced authentication for the previously exposed endpoints.
EPSS
Процентиль: 36%
0.00436
Низкий
4.8 Medium
CVSS3
Дефекты
CWE-306